Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:L/VI:H/VA:H/SC:L/SI:H/SA:HDefault status
unaffected
1.8.x (custom) before 1.8.51
affected
1.9.x (custom) before 1.9.51
affected
Description
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: License Center 1.8.51 and later License Center 1.9.51 and later
Problem types
Product status
1.8.x (custom) before 1.8.51
1.9.x (custom) before 1.9.51
Credits
Milan Solanki (LeoSecurity)
References
www.qnap.com/en/security-advisory/qsa-25-27